Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-73662

CVE-2026-73662: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.2

    High [CVE-2026-73662] FreePBX Music on Hold: Arbitrary command execution by authenticated administrator

    CVE-2026-73662Source published Source updated

    FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players in validateCustomConfiguration() in Music.class.php. An authenticated administrator can use options that write files, open control channels, or create Asterisk call files because applicationUsesDisallowedPlayerOption() does not reject those arguments, resulting in arbitrary command execution as the asterisk service user. This issue is fixed in version 17.0.7. An authenticated administrator can exploit dangerous command-line options when configuring media players, such as /usr/bin/mpg123. The CVE-2026-73662 vulnerability is in the FreePBX Music on Hold module's PHP code (Music.class.php), which fails to sanitize…

    Affected products in this advisory
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • 17.0.7
    Mitigation guidance
    • Red Hat products are not affected by this vulnerability. The vulnerable code is in the FreePBX Music on Hold module, which is not shipped in any Red Hat product.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery